DedeBIZ v6.2.11 was discovered to contain multiple remote code execution (RCE) vulnerabilities at /admin/file_manage_control.php via the $activepath and $filename parameters.
References
Link | Resource |
---|---|
http://dedebiz.com | Product |
https://github.com/yux1azhengye | Not Applicable |
https://github.com/yux1azhengye/mycve/blob/main/DedeBIZ_v6.2.11_RCE.pdf | Broken Link |
https://www.dedebiz.com | Product |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2023-09-26T00:00:00
Updated: 2023-09-26T12:19:17.241558
Reserved: 2023-09-18T00:00:00
Link: CVE-2023-43234
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-09-27T15:19:33.767
Modified: 2023-09-29T18:50:51.993
Link: CVE-2023-43234
JSON object: View
Redhat Information
No data.
CWE